Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 284

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Higher mortgage rates don't just keep buyers on the sidelines. Application denials rise too
Eli Manning's private equity firm acquires licensing company for NFL Flag in bet on youth sports
Bridge Over Troubled Water But Ok Calm Down Not THAT Troubled
Movie: Escape from Alcatraz
Game Changer: Rulette 2
Blackstone restricts flagship fund withdrawals as private asset fears reemerge
Stargate SG-1: Between Two Fires Rewatch
Here are Thursday's biggest analyst calls: Nvidia, Apple, Broadcom, Netflix, Oracle, Microsoft, CrowdStrike & more
Eli Manning weighs in on Giants QB Jaxson Dart's Trump rally fallout
Flesh-eating screwworm is confirmed in the U.S., officials say